The Internet of Some Corporation's Fully-Secured Things
*The blurring of who-owns-what, who pays for what and who digitally controls what is the central feature of the Internet of Things. Â It's not a bug. Â When you disrupt property relations, you also disrupt where the money, power and fame goes.
http://www.sys-con.com/node/3242299
@ThingsExpo: Blog Post
Knock Knock, Who's There? Exactly
As the Internet of Things continues to expand rapidly, the issue of access to applications is going to get messy
BYÂ LORI MACVITTIE
(…)
"The thing is that our security controls are still based on an IP world, where every person or device needs to be matched to an IP address so we can match that against a list and decide "yes" or "no" to access.
"If BYOD didn't teach us that's not feasible, the Internet of Things will.
"Bob doesn't just have a laptop and a phone. Now he also has a smart key, a smart car, and a smart watch. They're all "him" but yet they aren't. One might like to assume that if they're all coming out of the same network (the house network) over WiFi, then they all map back to the same public IP address cause, NAT works that way. And maybe that works well enough when every app and service needed is behind the corporate firewall. But they're not anymore. They're in the cloud, too, and across the Internet.
"We can't continue to craft firewall and access rules based on IP addresses. Not feasible and ultimately, it's not secure or accurate enough. We need ID-based access rules that not only consider who but what. Not just Bob, but Bob's phone. Not just Bill, but Bill's refrigerator. Not just Alice, but Alice's television.
"Identity will have to expand to include the notion of "ownership". Each of us becomes a "group" unto ourselves, with individual smart things and apps being a part of that group but having their own sub-identity and thus, access rights and constraints. Â (((Guess who writes those contracts and how big that shrink-wrap is.)))
"An application world is both about the apps that run those smart things (just because you can't see them doesn't mean they aren't there) and the apps that manage them (just because you can't see them in the data center / cloud doesn't mean they aren't there). We're going to need more flexible and dynamic means of determining not only who but what can access each of them at any given time. The pressure on identity management and access services is going to be incredible, because it's going to have to be the new perimeter. A traditional IP-based perimeter just isn't going to be enough to meet the new requirements for application delivery…."











